GDPR & Data Rights Notice
Effective Date: 01 June 2026
Last Updated: 01 June 2026
This GDPR & Data Rights Notice summarises how Avex AI processes personal data in accordance with applicable data protection laws, including the UK GDPR and, where applicable, the EU GDPR.
1. Our Data Protection Approach
Avex AI is built around a privacy-conscious architecture intended to minimise unnecessary exposure of personal data, particularly in AI-enabled workflows and imported financial data environments.
Our approach includes, where appropriate:
- data minimisation;
- purpose limitation;
- pseudonymisation and masking of identifying data;
- role-based access controls;
- regional data handling options; and
- limited retention windows for certain imported files.
2. Lawful Bases for Processing
We process personal data only where we have a lawful basis to do so, including:
- performance of a contract with you;
- our legitimate interests in operating, securing, and improving the Platform;
- your consent, where required;
- compliance with legal and regulatory obligations.
3. Open Banking and Consent-Based Access
Where you connect accounts using open banking or aggregation partners, data access is generally read-only, permissioned, and based on your explicit consent. Such consent may be revoked at any time through the relevant provider or, where available, through the Platform.
4. Pseudonymisation and AI Safety Controls
In line with the Platform’s intended design, directly identifying information may be pseudonymised before being submitted to certain AI or analytics processes.
This means personal data may be processed in a form that cannot be attributed to a specific person without the use of additional information held separately and subject to safeguards. While pseudonymisation reduces privacy risk, it does not render data fully anonymous.
5. Data Residency
Subject to service availability and technical implementation, users may be offered a choice of regional data handling or storage environments, including Zurich, New York City, and Dubai.
Where cross-border transfers occur, we take steps intended to ensure they are made in accordance with applicable data protection law.
6. Your Rights
Under applicable data protection law, you may have the right to:
- be informed about how your personal data is used;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain forms of processing;
- request portability of data you have provided to us; and
- withdraw consent where processing is based on consent.
7. Data Export and Erasure
Avex AI intends to provide users with access to data export functionality and account deletion controls in keeping with applicable privacy requirements. The current platform design contemplates rights of access and erasure, including a potential 30-day grace period prior to permanent deletion in certain cases.
8. Uploaded Files
Imported statements and similar documents may be retained only for a short processing window and may then be deleted automatically. Current product design provides for a 24-hour retention period for certain uploads.
9. Automated Processing
Avex AI uses automated systems and AI-assisted tools to generate informational outputs, scenario models, summaries, alerts, and analyses. These features support user interpretation and organisation of data, but do not constitute regulated advice or produce legally binding decisions.
We do not rely on solely automated decision-making to produce legal or similarly significant effects on users within the meaning of applicable data protection law, unless expressly stated and lawfully implemented.
10. Contact
To exercise your rights or ask questions about our data practices, contact:
Avex AI
Email: privacy@avexai.io
Address: ARTIFICIAL INTELLIGENCE MARS SRL, Str. Dr. Petre Herescu 12, Bucharest, Romania
